EP3857848A1 - Procédé d'allocation d'un identifiant à un noeud client, procédé d'enregistrement d'un identifiant, dispositif, noeud client, serveur et programmes d'ordinateurs correspondants - Google Patents
Procédé d'allocation d'un identifiant à un noeud client, procédé d'enregistrement d'un identifiant, dispositif, noeud client, serveur et programmes d'ordinateurs correspondantsInfo
- Publication number
- EP3857848A1 EP3857848A1 EP19802235.2A EP19802235A EP3857848A1 EP 3857848 A1 EP3857848 A1 EP 3857848A1 EP 19802235 A EP19802235 A EP 19802235A EP 3857848 A1 EP3857848 A1 EP 3857848A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- client
- identifier
- client node
- domain
- request
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1425—Traffic logging, e.g. anomaly detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/1458—Denial of Service
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/20—Network architectures or network communication protocols for network security for managing network security; network security policies in general
Definitions
- Method for allocating an identifier to a client node Method for registering an identifier, device, client node, server and corresponding computer programs.
- the field of the invention is that of communications within a communication network, for example an IP network, and in particular that of value-added IP services.
- the invention offers a solution to protect the communication network and the terminals connected to this network against computer attacks.
- the invention offers a solution allowing to allocate a unique identifier to a client node connected to the client domain and to register this identifier in association with an identifier of the client domain.
- the invention notably finds applications in the field of mitigation of attacks by denial of distributed services (in English DDoS, for “Distributed Douai of Service”), for example implementing, but not exclusively, a DOTS type architecture (in English "DDoS Open Threat Signaling”), as standardized by the IETF.
- denial of distributed services in English DDoS, for “Distributed Douai of Service”
- DOTS type architecture in English "DDoS Open Threat Signaling”
- a DDoS attack is an attempt to make resources, for example network or computing resources, unavailable to their users.
- resources for example network or computing resources
- Such attacks can be massively deployed by compromising a large number of hosts, and by using these hosts to amplify the attacks.
- DDoS attacks In order to overcome these DDoS attacks, detection and mitigation services for DDoS attacks are offered by certain access or service providers to their customers.
- Such mitigation services in English DPS for "DDoS Protection Services" can be hosted within the infrastructures operated by access providers or in the “cloud” (in French “cloud”). They make it possible in particular to distinguish “legitimate” traffic, i.e., data consented by the user, from “suspicious” traffic.
- tunnels To solve this problem, it was notably proposed to set up tunnels to force traffic (incoming or outgoing) on a site or a network intended to be inspected by the DPS service.
- this approach considerably increases the latency observed by the users and imposes constraints on the dimensioning of the DPS service to be able to handle all the traffic entering or leaving all the users of the network.
- the tunnels are potential and proven attack vectors.
- DOTS DOTS
- a specific architecture has been standardized by the IETF.
- DOTS allows a client node, said DOTS client, to inform a server, said DOTS server, that it has detected a DDoS attack and that appropriate actions are required to counter this attack.
- a DOTS client in that client domain can send a message to a DOTS server asking for help.
- the latter coordinates, with a mitigation entity (in English “mitigator”), the actions to be carried out so that the suspicious traffic, associated with the denial of service attack, is no longer routed to the client domain, while the traffic legitimate continues to be routed normally to the client domain.
- the mitigation entity can be co-located with the DOTS server.
- This solution uses two communication channels between a DOTS client and a server
- DOTS Signaling channel in English "DOTS Signal Channel"
- DOTS Data channel in English "DOTS Data Channel”
- the DOTS signaling channel is used when a DDoS attack is in progress.
- a DOTS client can use this channel to request help from a DOTS server.
- a DOTS client uses this signaling channel to send a request to the server informing it that the prefix "1.2.3.0/24" is undergoing a DDoS attack, so that the server can take actions to end the attack .
- Such a request is associated with a DOTS client identified by a unique identifier, noted for example CUID (“Unique Client I Dentifier”).
- a DOTS server can thus take adequate measures to end a DDoS attack on the one hand if the request from the DOTS client does not conflict with other requests from other DOTS clients in the same client domain, or with a filtering rule installed beforehand on the server by another DOTS client in the client domain, and on the other hand if the server is empowered to / configured to honor the last request received.
- the server can send an error message, for example of type 4.09 ("Conflict"), to inform the DOTS client.
- Such a signaling channel is described in particular in the document “Distributed Denial-of-Service Open Threat Signaling (DOTS) Signal Channel Specification”, draft-ietf-dots-signal-channel, Reddy, T. et al., January 2018.
- DSS Distributed Denial-of-Service Open Threat Signaling
- the DOTS data channel is used when no DDoS attack is in progress.
- a DOTS client can use this channel to install filtering rules, such as filtering traffic received from certain addresses or traffic destined for a given node.
- filtering rules such as filtering traffic received from certain addresses or traffic destined for a given node.
- a DOTS client can use this DOTS data channel to request the server to block all traffic to the prefix "1.2.3.0/24", or all UDP traffic destined for port number 443.
- the DOTS server can install filtering rules in response to a request sent by a DOTS client, if this request does not conflict with other requests from other DOTS clients in the same client domain or with an existing filter rule.
- the server can send an error message, for example of type 409 ("Conflict"), to inform the DOTS client.
- Such a data channel is described in particular in the document “Distributed Denial-of- Service Open Threat Signaling (DOTS) Data Channel”, draft-ietf-dots-data-channel, Boucadair M. et al., December 2017.
- DSS Distributed Denial-of- Service Open Threat Signaling
- a DOTS server refuses to process an attack mitigation request sent by a DOTS client while the attack is real, or refuses filtering requests sent by a DOTS client (an objective of filtering requests being to anticipate DDoS attacks). Such a refusal may in particular occur when these filtering requests are in conflict with filtering rules installed by other DOTS clients in the same client domain.
- the invention relates to a method of allocating an identifier to a first client node of a client domain, said first client node being able to manage the traffic associated with the client domain for its purpose. protection against a computer attack, said method comprising:
- the recording in a local memory of an association between the allocated identifier and the identification information of the first client node;
- the invention thus provides a controlled management of identifiers used by client nodes in a client domain to communicate with each other and with a traffic management server associated with the client domain. According to this embodiment, it guarantees the uniqueness of the identifier allocated to the first node when it becomes active in the domain and therefore makes it possible to avoid identification conflicts between active nodes.
- the method can be implemented by another client node, benefiting from privileges in the client domain, said master client, or by a dedicated software instance, called CMI (CUID Management Instance) which interfaces with the client node master.
- CMI CMI Management Instance
- the method comprises a modification of the association recorded in the local memory.
- the management of the identifier allocated to the first client node is controlled during the entire period of connection of the node to the client domain.
- the detected event belongs to a group comprising:
- the event can concern either a change in the activity of the first client node, or in the security or administration policy of the client domain.
- the modification comprises the deletion of the registration
- the method comprises the emission of a request for cancellation of the registration of the allocated identifier intended for the server.
- this first exemplary embodiment allows the repercussion at the server level of the deletion of the association (client, cuid).
- the identifier allocated to the first client is thus released and can be assigned to another active client node.
- the modification comprises replacing, in the recording of the local memory, the identification information of the first client with identification information of a second client in the domain.
- this second embodiment makes it possible to facilitate the replacement of the first client node by a second, without modifying the mitigation actions installed by the first client node and, consequently, without disturbing the execution in progress of these mitigation actions.
- the second client node will resume processing of the mitigation actions previously implemented by the first client node. It is not necessary, according to this example, to pass this modification on to the server, since it already stores the correct association between the unique identifier of the client node and the domain identifier.
- the request received further comprising a request for allocation of a management delegation attribute, said attribute being intended to be specified by another client node in a request for processing a management rule traffic transmitted to the server to delegate the management of said traffic management rule to the first client node
- the method comprises:
- the response sent to the first client node includes the allocated delegation attribute.
- the delegation attribute can be specified by the first client node during the installation of a rule (filtering, ACL, etc.) after the execution of a mitigation action to the server, so as to indicate that it grants a delegation on the mitigation action.
- the delegation attribute is then stored by the server in association with the installed rule.
- Knowledge of this delegation attribute allocated to the first client node can be transmitted to another client node in order to allow it to modify the rule installed by the first client node.
- the second client node must insert the value of this delegation attribute in its request to modify the rule concerned and sent to the server.
- the response further includes the delegation attribute allocated to at least one other client node.
- the delegation attribute allocated to at least one other client node.
- the master client node or the CMI entity wishes to deactivate the delegation procedure, for example because it induces an excessive load on certain client nodes in the domain.
- the invention relates to a method of registering an identifier allocated to a client node capable of managing the traffic associated with a client domain for the purpose of its protection against a computer attack, implemented in a server, the method comprising:
- the invention proposes to register at the server level an association between the unique identifier allocated to the client node and the identifier of the client domain, which makes it possible to secure exchanges between the client nodes and the server. to manage the traffic associated with the client domain and to guarantee the global uniqueness of the identifier consisting of the pair ⁇ CUID, CDID ⁇ .
- the method comprises searching for said record in a memory and rejecting the request if said record was not found.
- the method comprises:
- This delegation procedure thus makes it possible to migrate the management of a mitigation action in the event of unavailability of the client node at the origin of its installation. It is particularly interesting, in the event of an attack, when a client node has previously issued a mitigation request to the server which has replied that there is a conflict between its request and at least one rule already installed by another client node following the execution of a mitigation action. With the invention, the client node which detects the attack can take advantage of the delegation procedure to request the server to modify the rule so that it no longer hinders the mitigation of the attack in progress. The reliability of the attack mitigation service is therefore increased.
- the method comprises the deletion of said registration and the deletion of the traffic management rules installed by the first client node.
- the method of registering an identifier comprises the notification of the other client nodes active in the client domain, prior to said removal of the traffic management rules installed by the first client node.
- the invention relates to a device for allocating an identifier to a first client node capable of managing the traffic associated with a client domain for the purpose of its protection against a computer attack, said device comprising at least a programmable calculation machine or a dedicated calculation machine configured to implement:
- the recording in a local memory of an association between the allocated identifier and the identification information of the first client node;
- the invention relates to one or more computer programs comprising instructions for implementing a method according to at least one embodiment of the invention, when this or these programs is / are executed by a processor.
- the invention relates to one or more non-removable or partially or completely removable information carriers, readable by a computer, and comprising instructions for one or more computer programs for execution of a method according to at least one embodiment of the invention.
- the methods according to the invention can therefore be implemented in various ways, in particular in wired form and / or in software form.
- FIG. 1 illustrates an example of a communication network implementing a method of allocating an identifier of a client node and a method of registering an identifier, according to an embodiment of the invention
- FIG. 2 presents the main steps of the method for allocating an identifier according to an embodiment of the invention
- FIG. 3 presents the main steps of the method of registering an identifier according to an embodiment of the invention
- FIGS. 4A and 4B illustrate examples of messages exchanged between a first client node, a master client and a server for the allocation of an identifier to the first client of a client domain and its recording according to an embodiment of the invention
- FIGS. 5A and 5B illustrate examples of application of the invention to make the exchanges between the client nodes and the server more reliable
- FIGS. 6A to 6D illustrate examples of messages exchanged between the first client node, the master client and the server to delete the identifier allocated to the first client node according to an embodiment of the invention
- FIG. 7 details the steps implemented by the server to process a modification request by a first client node of a management action installed by a second client node, according to an embodiment of the invention
- FIGS. 8A to 8B illustrate the resolution of a conflict between traffic management actions according to an embodiment of the invention
- FIGS. 9A to 9C illustrate examples of messages exchanged for the implementation of a delegation procedure between client nodes according to an embodiment of the invention.
- FIG. 10 schematically illustrates the hardware structure of a client node and a server according to an embodiment of the invention.
- the general principle of the invention is based on the allocation of a unique identifier to a client node forming part of a client domain, but also on the registration of this identifier in association with an identifier of the client domain, and on the use of this unique identifier to make protection against denial of service attacks within the domain more efficient and more reliable.
- the client domain 11 includes one or more machines, also called nodes.
- domain means a set of machines or nodes placed under the responsibility of the same entity. We consider for example several client nodes Cl, C2, Cm belonging to the client domain 11, communicating with a server S 12.
- the server 12 does not belong to the client domain 11. According to another example not shown, the server 12 can belong to the client domain 11.
- the client nodes C1, C2 and Cm 114 are DOTS clients and the server S is a DOTS server.
- the client nodes Cl, C2 and Cm and the server S can thus communicate via the DOTS signaling and data channels defined in relation to the prior art, to inform the server that a DDoS attack has been detected and that appropriate actions are required.
- a DOTS request can be, for example:
- an alias management message for example intended to associate an identifier with one or more network resources located in the client domain
- a signaling message to request mitigation of a denial of service attack with a DOTS server the server being able, on reception of such a message, to initiate the actions necessary to end the attack, or
- a traffic management rules management message for example filtering, including a request to a DOTS server to install (or have installed), modify or delete an access control list (ACL for "Access Control List") for the mitigation of an attack.
- ACL access control List
- a “request for processing” will denote a request to install one or more explicit filtering rules, an access control list, and more generally any action. that a DOTS client node can request from the server for the mitigation of an attack and more generally, the application of a security policy targeting the domain that hosts the DOTS client.
- a DOTS request can be sent from a DOTS client, belonging to a DOTS client domain, to a DOTS server or to a plurality of DOTS servers.
- a DOTS domain can accommodate one or more DOTS clients. In other words, several client nodes in a client domain can have DOTS functions.
- DOTS communications between a client domain and a server domain can be direct, or established via DOTS gateways (in English "DOTS gateways"), not shown. These gateways can be hosted within the client domain, the server domain, or both.
- DOTS gateways in English "DOTS gateways"
- a client node in the client domain can communicate directly with the server, or transmit a request to a gateway in the client domain which communicates directly with the server or with a gateway in the server domain, or transmit a request to a gateway of the server domain that communicates with the server.
- a DOTS gateway located in a client domain is considered by a DOTS server as a DOTS client.
- a DOTS gateway located in a server domain is considered by a DOTS client as a DOTS server. If there is a DOTS gateway in a server domain, authentication of DOTS clients can be entrusted to the DOTS gateway in the server domain.
- a DOTS server can be configured with the list of DOTS gateways active within its domain and the server can delegate some of its functions to these trusted gateways. In particular, the server can safely use the information provided by a gateway appearing in a list declared to the server and maintained by the latter, by means of an ad hoc authentication procedure (for example, explicit configuration of the list by the 'authorized administrator of the server, retrieving the list from an authentication server such as an AAA server (for "Authentication, Authorization and Accounting”), etc.).
- DOTS architecture one or more DOTS clients in a client domain, no DOTS gateway, one or more DOTS gateways in the client domain or in the server domain, client domain separate from the server domain, etc.
- DOTS Distributed Denial-of-Service Open Threat Signaling
- FIG. 2 illustrates the main steps of the method of allocating an identifier to a first client node C1 according to an embodiment of the invention.
- This process can be implemented by another client node in the client domain, benefiting from privileges with the server S, called the master client Cm, or by a new dedicated software instance, called CMI (for “CUID Management Instance”, in English) which interfaces with a master client node CL
- CMI for “CUID Management Instance”, in English
- the DOTS Cl client When the DOTS Cl client starts up, it contacts its master client Cm or the CMI instance to request in 21 the allocation of a DOTS client identifier or cuid. To do this, the client DOTS Cl sends an allocation request message MREQID or GET () to the master client Cm, as illustrated in FIG. 4A. Upon receipt of the MREQID or GET () message by the master client Cm DOTS (or the CMI instance), the latter verifies that this client Cl is authorized to invoke the DOTS service. If necessary, the master client Cm obtains at 22 a list of identifiers currently used in the field, for example by consulting a table stored in memory, and chooses at 23 an identifier cuid_cl which is not part of this list.
- the DOTS Cm client (or the CMI instance) ensures by default that two clients in the client domain do not use the same identifier 'cuid'. Note that this constraint can be relaxed during the securing or replacement phases of one DOTS client with another.
- the master client Cm stores in 24 the pair formed by the allocated unique identifier and the identifier of the client Cl in memory, for example a local memory. Then, and in order to improve the robustness of the DOTS service, the DOTS Cm master client contacts at 25 the S server at 27Cm to register the new identifier activated within the DOTS client domain for the client Cl. As illustrated in FIG.
- MREQREG Registration request message
- REGISTER_REQ REGISTER_REQ
- This message can include the DOTS cuid identifier (s) of the Cl client alone or of several clients.).
- MREPREG MREPREG
- REGISTER_ACK REGISTER_ACK
- it sends in 26 to the client Cl an acknowledgment message MREPID or SET (cuid_cl) including the identifier cuid_cl which it allocated to it, as illustrated in Figure 4A.
- the client Cm can repeat the process in order to reallocate a new identifier to the client Cl and request the registration of the new identifier cuid_cl from the server S.
- the client domain upon detection of an event occurring in the client domain, such as the inactivity of the client node Cl, or its disconnection or even a change in the security policy of the client domain at 27, it modifies at least locally the 28 registration of the identifier cuid_cl.
- an event occurring in the client domain such as the inactivity of the client node Cl, or its disconnection or even a change in the security policy of the client domain at 27, it modifies at least locally the 28 registration of the identifier cuid_cl.
- the server S On reception at 31 of a request for registration MREQREG () or REGISTER_REQ of an identifier cuid_cl for the client Cl of the client domain 11 coming from the master client Cm, as illustrated in FIG. 4B, the server S performs the checks of security (not shown) already mentioned. If successful, it obtains in 32 an identifier 'cdid' (for "Client Domain I Dentifier", in English) of the client domain 11 to which the client Cl is attached. For example, a DOTS server identifies DOTS clients belonging to the same domain by the cdid attribute.
- the domain identifier can be calculated locally by the server or communicated by another trusted entity (typically, a DOTS relay from its server domain), or both. No assumption is made as to the structure of the cdid. It then checks at 33 if an association between this client identifier cuid_cl and this domain identifier 'cdid' is already stored in memory. If it finds one, it rejects the registration request at 35 by sending the master client a rejection response MREPREQ (rej). If it does not find one, it processes the recording request at 34 by storing the pair (cuid, cdid) of client Cl in memory M2. It then acknowledges the registration request with an MREPREG (ack) or REGISTER-ACK () message, as shown in Figure 4B.
- MREPREG ack
- REGISTER-ACK REGISTER-ACK
- a mitigation solution such as the installation of a traffic management rule of the type filtering of Rk traffic
- this request coming from a client identified by the identifier cuid_cl
- the server checks in 37 that the identifier cuid_cl is validly saved in its memory in association with the identifier of the client domain from which the request comes . If successful, it processes the request at 38, otherwise it rejects it.
- the verification procedure according to the invention implemented by the DOTS server to process a DOTS request emanating from a DOTS client makes the service more reliable even in the event of the theft of security identities by a malicious entity.
- Table 1 an example of an extract from a list of DOTS clients as maintained by a master DOTS client Cm is presented.
- the table indicates three active DOTS clients for this domain.
- the invention does not assume any particular structure for the tables maintained by the CMI / DOTS master client instance.
- the information concerning the allocation of the identifier of the DOTS client is communicated by the CMI instance to the DOTS master client Cm.
- the PUT request is relayed by a DOTS relay from the server domain.
- Table 2 An example of extract from a list of clients as maintained by the server S.
- the table indicates 5 active DOTS clients, 3 of which belong to the “here” domain. example ”of the master client Cm.
- FIGS. 5A and 5B To illustrate the advantages of the method for allocating a unique identifier according to the invention, the examples of situations in FIGS. 5A and 5B are considered.
- the master client C1 first registers with the server S the identifier cuid_c3 which he has allocated to the client C3.
- a malicious DOTS client C4 belonging to another domain 12 contacts the server S, requesting the implementation of a management action on behalf of the client C3, that is to say in using its identifier cuid_c3, the server detects that the association (cuid_c3, cdid) is wrong and rejects the request.
- the event detected at 27 is an event relating to a change in the activity of client nodes registered in the domain or in the security policy applied within the domain.
- a master client node Cm uses the unique identifiers to react to this event. These include, for example:
- the master client Cm can decide to delete the registration of one or more client nodes with the server S.
- the record deletion message can include one or more DOTS client identifiers from a client domain.
- the DOTS S server proceeds to delete the clients listed in its tables (after the usual security checks).
- the event detected by the master client Cm is the receipt of an explicit request to delete the record from a client node C1 in the client domain.
- the master client Cm proceeds to modify the registration of the identifier of the client Cl.
- the master client C1 acknowledges the request from the client Cl with a response message MREPSUP (ack) and transmits a request for deleting the record MREQUNREG () from the client Cl to the server S.
- Ce last removes the association (cuid_cl, cdid) from its table and responds to the master client Cm with an acknowledgment message.
- the cuid_cl identifier is thus released at the level of the server S, which will then delete the actions installed with this identifier.
- the DOTS server S informs the other clients of the domain of the existence of these rules, so that they can reinstall them.
- the DOTS agents clients and servers
- the DOTS agents support the “RESTCONF and HTTP Transport for Event Notifications” mechanism, as specified in the document “RESTCONF Transport for Event Notifications, draft-ietf-netconf- restconf -notif, E. Voit et al., Sep 2018 ”.
- the client C2 When the client C2 disconnects or when the server detects an inactivity of the client C2 for a given period, it identifies the filters associated with this client C2, and then notifies the other client nodes of the same client domain such as Cl of its intention to remove the traffic management rules associated with the client C2.
- the client C1 can decide to take responsibility for certain rules initially associated with the client C2. To do this, it transmits a POST type request to the server S asking it to migrate certain rules of the client C2 to its name. The server S migrates these rules, and sends an acknowledgment message of type “204 created” to the client Cl (ie, the identifier of the client node Cl will be maintained by the server as being responsible for managing these rules).
- the master client Cm acknowledges the request from the client Cl by a response message MREPSUP (ack). To avoid disturbing the operation of the DOTS domain 11, it does not ask the server S to delete the registration of the identifier cuid_cl from the client Cl, but it reallocates this identifier to another client C2 in the domain 11. In this way, it replaces the Cl client with another client in the domain without affecting the state maintained by the S server.
- MREPSUP response message
- the server can accept its request because the client C2 is validly identified .
- the server S receives at 36 a request for processing a rule Rk from the client Cl.
- identifier cuid_cl It checks in 37 that the identifier cuid_cl is indeed registered in association with the identifier of the client domain cdid. If necessary, it searches in 371 for a record associating the identifier cuid_cl with the rule Rk identified by the attribute rk. If this is the case, the client Cl is at the origin of the installation of the rule Rk which he wishes to modify. The server S performs the modification requested at 38.
- this new attribute "THIRD_PARTY_NONCE” is informed by the DOTS C2 client when the Rk rule is created with the server S.
- This attribute includes a unique identifier, such as the identifier cuid_cl of the client Cl.
- This delegation procedure allows a client node in the client domain to modify actions installed by another client in this client domain, such as, for example, traffic filter rules that are out of date or in conflict with the installation of other filter rules. , for example for the implementation of a mitigation solution against a DDoS attack.
- the delegation is activated only by the client C1 for the benefit of the client C2.
- Client C2 does not designate client Cl as beneficiary of a delegation;
- the delegation is activated by the two clients: Cl delegates to C2 and vice versa.
- THIRD_PARTY_NONCE o the same value of the THIRD_PARTY_NONCE attribute is used by the two customers o separate values are used by each of the customers.
- my_acl for which the client node C2 identified by the identifier cuid_c2, specifies to the server that it supports the delegation by indicating the value "263afd79-835c-4ee7-9535- df245cf28d9a" for the attribute TFIIRD_PARTY_NONCE in its request.
- the client node C1 requests the server S so that it implements a solution for mitigating this attack by sending in 81C1 the following message:
- Client node C1 receives this error message at 87C1. Contrary to the state of the art, the client node Cl returns at 88C1 a request to modify the filtering rule Rk to the server SI to resolve the conflict. In this example, it is assumed that the client node Cl adds a new entry to the existing rule "my-acl" to block only the traffic intended for the address "1.2.3.1/32". For example, the request for modification of Rk which it addresses to the server SI takes the following form:
- the value of the attribute "THIRD_PARTY_NONCE" is allocated by the CMI / master client Cm instance, at the same time as the identifier 'cuid'.
- the value of the delegation attribute can be obtained by static or dynamic configuration, for example, using the DHCP protocol.
- the client node C1 transmits an allocation request MREQID () or GET (cuid, THIRD_PARTY_NONCE) with an identifier 'cuid_cl' and a delegation attribute.
- the CMI instance or the master client node Cm can deactivate this delegation procedure by not returning any delegation attribute value to the client Cl as shown in Figure 9B.
- the absence of the THIRD_PARTY_NONCE attribute in the response received from the CMI is an explicit indication to inform the client node C1 that the DOTS delegation procedure is deactivated.
- the delegation procedure can induce a computation overload for the client node which takes over from another client node for the management of its actions in progress. If the load of said relay node reaches a certain threshold, for example 80% of the central processing unit or CPU (for “Central Processing Unit”, in English), the delegation procedure could then be deactivated. The entity in charge of activating the delegation procedure can in particular be informed of a threshold being exceeded by conventional notification means such as an "SNMP trap".
- the master client node indicates in its response to the client node C1, not only the value of the delegation attribute which it has allocated to it, but also that which it has allocated to other client nodes in the same client domain. It is understood that in this case, all the client nodes of the client domain share the same value of the delegation attribute.
- the registration by the server S of an association between the unique identifier allocated to the client node by the master client node or the entity CMI, and the client domain identifier 11, not only makes exchanges between DOTS agents more reliable, but also facilitates and makes more robust the protection implemented by the S server against DDoS attacks.
- a client node Cm comprises a memory 101cm comprising a buffer memory, a processing unit 102c m , equipped for example with a programmable calculation machine or with a dedicated calculation machine, for example a processor P, and controlled by the computer program 103c m , implementing steps of the method of allocating an identifier to a first client node in charge of managing the traffic associated with a client domain according to an embodiment of the 'invention.
- the code instructions of the computer program 103c m are for example loaded into a RAM memory before being executed by the processor of the processing unit 102c m ⁇
- the processor of the processing unit 102c m implements process steps allocation of the identifier described above, according to the instructions of the computer program 103 Cm , for:
- a server S comprises a memory 101 s comprising a buffer memory, a processing unit 102 $ , equipped for example with a programmable calculation machine or with a dedicated calculation machine, for example a processor P, and controlled by the computer program 103 $ , implementing steps of the method of registering an identifier according to an embodiment of the invention.
- the code instructions of the computer program 103 $ are for example loaded into a RAM memory before being executed by the processor of the processing unit 102s.
- the processor of the processing unit 102 $ implements steps of the method for registering an identifier described above, according to the instructions of the computer program 103 $ , for:
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- General Engineering & Computer Science (AREA)
- Computer Networks & Wireless Communication (AREA)
- Signal Processing (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
- Computer And Data Communications (AREA)
Abstract
Description
Claims
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| FR1859044A FR3086776A1 (fr) | 2018-09-28 | 2018-09-28 | Procede d'allocation d'un identifiant a un nœud client, procede d'enregistrement d'un identifiant, dispositif, nœud client, serveur et programmes d'ordinateurs correspondants. |
| PCT/FR2019/052279 WO2020065232A1 (fr) | 2018-09-28 | 2019-09-26 | Procédé d'allocation d'un identifiant à un nœud client, procédé d'enregistrement d'un identifiant, dispositif, nœud client, serveur et programmes d'ordinateurs correspondants |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| EP3857848A1 true EP3857848A1 (fr) | 2021-08-04 |
| EP3857848B1 EP3857848B1 (fr) | 2022-08-31 |
Family
ID=65685535
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP19802235.2A Active EP3857848B1 (fr) | 2018-09-28 | 2019-09-26 | Procédé d'allocation d'un identifiant à un noeud client, procédé d'enregistrement d'un identifiant, dispositif, noeud client, serveur et programmes d'ordinateurs correspondants |
Country Status (6)
| Country | Link |
|---|---|
| US (1) | US12218955B2 (fr) |
| EP (1) | EP3857848B1 (fr) |
| CN (1) | CN112771833B (fr) |
| ES (1) | ES2932499T3 (fr) |
| FR (1) | FR3086776A1 (fr) |
| WO (1) | WO2020065232A1 (fr) |
Families Citing this family (3)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| FR3086821A1 (fr) * | 2018-09-28 | 2020-04-03 | Orange | Procedes de collaboration et de demande de collaboration entre services de protection associes a au moins un domaine, agents et programme d’ordinateur correspondants. |
| US11637710B2 (en) * | 2019-12-10 | 2023-04-25 | Jpmorgan Chase Bank, N.A. | Systems and methods for federated privacy management |
| WO2022152377A1 (fr) * | 2021-01-14 | 2022-07-21 | Telefonaktiebolaget Lm Ericsson (Publ) | Atténuation d'attaques ddos |
Family Cites Families (14)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP1655928A1 (fr) * | 2004-11-05 | 2006-05-10 | Hitachi, Ltd. | Procédé et dispositif pour assigner un identificateur unique à un noeud de réseau |
| US7653352B2 (en) * | 2005-12-22 | 2010-01-26 | Motorola, Inc. | Method and apparatus for self-assigning addresses |
| US20080161008A1 (en) * | 2006-12-27 | 2008-07-03 | Enoch Porat | Method and system for identification of a communication device in a wireless communication network |
| US9137135B2 (en) * | 2011-11-14 | 2015-09-15 | Jds Uniphase Corporation | Selective IP address allocation for probes that do not have assigned IP addresses |
| US8935430B2 (en) * | 2012-06-29 | 2015-01-13 | Verisign, Inc. | Secondary service updates into DNS system |
| CN103067385B (zh) * | 2012-12-27 | 2015-09-09 | 深圳市深信服电子科技有限公司 | 防御会话劫持攻击的方法和防火墙 |
| CN104618351A (zh) * | 2015-01-15 | 2015-05-13 | 中国科学院信息工程研究所 | 一种识别dns欺骗攻击包及检测dns欺骗攻击的方法 |
| CN105262722B (zh) * | 2015-09-07 | 2018-09-21 | 深信服网络科技(深圳)有限公司 | 终端恶意流量规则更新方法、云端服务器和安全网关 |
| CN105610852A (zh) | 2016-01-15 | 2016-05-25 | 腾讯科技(深圳)有限公司 | 处理ack洪泛攻击的方法和装置 |
| US20170345009A1 (en) | 2016-05-25 | 2017-11-30 | Mastercard International Incorporated | Systems and Methods for Use in Facilitating Network Transactions |
| US10728280B2 (en) * | 2016-06-29 | 2020-07-28 | Cisco Technology, Inc. | Automatic retraining of machine learning models to detect DDoS attacks |
| US10382480B2 (en) * | 2016-10-13 | 2019-08-13 | Cisco Technology, Inc. | Distributed denial of service attack protection for internet of things devices |
| US10305931B2 (en) * | 2016-10-19 | 2019-05-28 | Cisco Technology, Inc. | Inter-domain distributed denial of service threat signaling |
| US9756075B1 (en) * | 2016-11-22 | 2017-09-05 | Acalvio Technologies, Inc. | Dynamic hiding of deception mechanism |
-
2018
- 2018-09-28 FR FR1859044A patent/FR3086776A1/fr not_active Withdrawn
-
2019
- 2019-09-26 WO PCT/FR2019/052279 patent/WO2020065232A1/fr not_active Ceased
- 2019-09-26 US US17/279,999 patent/US12218955B2/en active Active
- 2019-09-26 CN CN201980064096.9A patent/CN112771833B/zh active Active
- 2019-09-26 EP EP19802235.2A patent/EP3857848B1/fr active Active
- 2019-09-26 ES ES19802235T patent/ES2932499T3/es active Active
Also Published As
| Publication number | Publication date |
|---|---|
| CN112771833B (zh) | 2023-06-06 |
| EP3857848B1 (fr) | 2022-08-31 |
| FR3086776A1 (fr) | 2020-04-03 |
| US12218955B2 (en) | 2025-02-04 |
| CN112771833A (zh) | 2021-05-07 |
| US20220038473A1 (en) | 2022-02-03 |
| WO2020065232A1 (fr) | 2020-04-02 |
| ES2932499T3 (es) | 2023-01-20 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP4066461B1 (fr) | Procédé de coordination de la mitigation d'une attaque informatique, dispositif et système associés | |
| FR3041493A1 (fr) | Equipement pour offrir des services de resolution de noms de domaine | |
| EP3857848B1 (fr) | Procédé d'allocation d'un identifiant à un noeud client, procédé d'enregistrement d'un identifiant, dispositif, noeud client, serveur et programmes d'ordinateurs correspondants | |
| EP3939232B1 (fr) | Mitigation d'attaques informatiques | |
| FR2962621A1 (fr) | Acces confidentiel ou protege a un reseau de noeuds repartis sur une architecture de communication a l'aide d'un serveur de topologie | |
| CH718976A2 (fr) | Gestion des pares-feux d'entreprise et isolement du réseau. | |
| EP3815335A1 (fr) | Procédés de vérification de la validité d'une ressource ip, serveur de contrôle d'accès, serveur de validation, noeud client, noeud relais et programme d'ordinateur correspondants | |
| EP3972218A1 (fr) | Procédé d'accès sécurisé à des ressources via un réseau de télécommunication et système de contrôle associé | |
| EP3788762B1 (fr) | Procédé d'envoi d'une information et de réception d'une information pour la gestion de réputation d'une ressource ip | |
| EP3857849B1 (fr) | Procédés de protection d'un domaine client, noeud client, serveur et programmes d'ordinateur correspondants | |
| WO2020002853A1 (fr) | Procédés de gestion du trafic associé à un domaine client, serveur, nœud client et programme d'ordinateur correspondants | |
| FR3136075A1 (fr) | Infrastructure de sécurité ; procédé et produit programme d’ordinateur associés. | |
| FR3087603A1 (fr) | Technique de collecte d'informations relatives a un flux achemine dans un reseau | |
| FR3131023A1 (fr) | Procédés d’identification d’au moins un serveur de mitigation et de protection d’un domaine client contre une attaque informatique, dispositifs, signal et dispositifs correspondants | |
| WO2020065233A1 (fr) | Procédé de collaboration et de demande de collaboration entre services de protection associés à au moins un domaine, agents et programme d'ordinateur correspondants | |
| FR3145253A1 (fr) | Procédé de révocation d’un jeton de certification permettant d’authentifier l’établissement d’une connexion entre deux équipements de communication, dispositifs et programmes d’ordinateur correspondants | |
| WO2021105617A1 (fr) | Procede d'assistance pour la gestion d'une attaque informatique, dispositif et systeme associes | |
| FR3157769A1 (fr) | Procédé d’accès à un service par un dispositif de communication via au moins un réseau de communication |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: UNKNOWN |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE INTERNATIONAL PUBLICATION HAS BEEN MADE |
|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| 17P | Request for examination filed |
Effective date: 20210311 |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| DAV | Request for validation of the european patent (deleted) | ||
| DAX | Request for extension of the european patent (deleted) | ||
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R079 Ref document number: 602019019067 Country of ref document: DE Free format text: PREVIOUS MAIN CLASS: H04L0029060000 Ipc: H04L0009400000 |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: GRANT OF PATENT IS INTENDED |
|
| INTG | Intention to grant announced |
Effective date: 20220120 |
|
| RIC1 | Information provided on ipc code assigned before grant |
Ipc: H04L 9/40 20220101AFI20220110BHEP |
|
| GRAJ | Information related to disapproval of communication of intention to grant by the applicant or resumption of examination proceedings by the epo deleted |
Free format text: ORIGINAL CODE: EPIDOSDIGR1 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: REQUEST FOR EXAMINATION WAS MADE |
|
| GRAP | Despatch of communication of intention to grant a patent |
Free format text: ORIGINAL CODE: EPIDOSNIGR1 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: GRANT OF PATENT IS INTENDED |
|
| INTC | Intention to grant announced (deleted) | ||
| INTG | Intention to grant announced |
Effective date: 20220330 |
|
| GRAS | Grant fee paid |
Free format text: ORIGINAL CODE: EPIDOSNIGR3 |
|
| GRAA | (expected) grant |
Free format text: ORIGINAL CODE: 0009210 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE PATENT HAS BEEN GRANTED |
|
| AK | Designated contracting states |
Kind code of ref document: B1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| REG | Reference to a national code |
Ref country code: CH Ref legal event code: EP Ref country code: GB Ref legal event code: FG4D Free format text: NOT ENGLISH |
|
| REG | Reference to a national code |
Ref country code: AT Ref legal event code: REF Ref document number: 1516113 Country of ref document: AT Kind code of ref document: T Effective date: 20220915 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R096 Ref document number: 602019019067 Country of ref document: DE |
|
| REG | Reference to a national code |
Ref country code: IE Ref legal event code: FG4D Free format text: LANGUAGE OF EP DOCUMENT: FRENCH |
|
| REG | Reference to a national code |
Ref country code: LT Ref legal event code: MG9D |
|
| REG | Reference to a national code |
Ref country code: NL Ref legal event code: MP Effective date: 20220831 |
|
| REG | Reference to a national code |
Ref country code: ES Ref legal event code: FG2A Ref document number: 2932499 Country of ref document: ES Kind code of ref document: T3 Effective date: 20230120 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: SE Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 Ref country code: RS Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 Ref country code: NO Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20221130 Ref country code: LV Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 Ref country code: LT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 Ref country code: FI Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 |
|
| REG | Reference to a national code |
Ref country code: AT Ref legal event code: MK05 Ref document number: 1516113 Country of ref document: AT Kind code of ref document: T Effective date: 20220831 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: PL Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 Ref country code: IS Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20221231 Ref country code: HR Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 Ref country code: GR Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20221201 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: SM Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 Ref country code: RO Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 Ref country code: PT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20230102 Ref country code: DK Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 Ref country code: CZ Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 Ref country code: AT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 |
|
| REG | Reference to a national code |
Ref country code: CH Ref legal event code: PL |
|
| REG | Reference to a national code |
Ref country code: BE Ref legal event code: MM Effective date: 20220930 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: SK Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 Ref country code: MC Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 Ref country code: EE Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 |
|
| REG | Reference to a national code |
Ref country code: DE Ref legal event code: R097 Ref document number: 602019019067 Country of ref document: DE |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: NL Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 Ref country code: LU Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20220926 Ref country code: AL Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 |
|
| PLBE | No opposition filed within time limit |
Free format text: ORIGINAL CODE: 0009261 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: NO OPPOSITION FILED WITHIN TIME LIMIT |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: LI Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20220930 Ref country code: IE Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20220926 Ref country code: CH Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20220930 |
|
| 26N | No opposition filed |
Effective date: 20230601 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: SI Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: BE Free format text: LAPSE BECAUSE OF NON-PAYMENT OF DUE FEES Effective date: 20220930 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: CY Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: MK Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 Ref country code: HU Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT; INVALID AB INITIO Effective date: 20190926 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: TR Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: BG Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 |
|
| PG25 | Lapsed in a contracting state [announced via postgrant information from national office to epo] |
Ref country code: MT Free format text: LAPSE BECAUSE OF FAILURE TO SUBMIT A TRANSLATION OF THE DESCRIPTION OR TO PAY THE FEE WITHIN THE PRESCRIBED TIME-LIMIT Effective date: 20220831 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: DE Payment date: 20250820 Year of fee payment: 7 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: IT Payment date: 20250820 Year of fee payment: 7 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: GB Payment date: 20250820 Year of fee payment: 7 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: FR Payment date: 20250821 Year of fee payment: 7 |
|
| PGFP | Annual fee paid to national office [announced via postgrant information from national office to epo] |
Ref country code: ES Payment date: 20251001 Year of fee payment: 7 |